Multiple vulnerabilities in WordPress (August 07, 2026)
Multiple vulnerabilities have been discovered in WordPress. Some of them allow an attacker to cause privilege escalation, breach of data confidentiality and server-side request forgery (SSRF).
CSIRTS triage
- What
- Multiple vulnerabilities in WordPress enable privilege escalation, data breach, and server-side request forgery attacks.
- Who is affected
- WordPress installations running affected versions; both self-hosted and plugin users.
- Urgency
- Moderate to high; privilege escalation and SSRF pose direct security risks.
- Action
- Update WordPress and all plugins to the latest patched versions immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch WordPress
Get an email when a new WordPress advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0979/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64638 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for WordPress
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-64638: WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a s…nvd · 2026-08-07
- mediumCVE-2026-48093: The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scri…nvd · 2026-08-07
- unknownCVE-2026-48094: The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulner…nvd · 2026-08-07
- high[NEW] [high] WordPress: Multiple vulnerabilitiescert-bund · 2026-08-07
- mediumCVE-2026-15239: The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its …nvd · 2026-08-07
- mediumCVE-2026-15211: The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment …nvd · 2026-08-07
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Progress Telerik (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Debian Linux kernel (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Google Chrome (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Debian LTS Linux kernel (August 07, 2026)2026-08-07